Decentraland issued a security notice warning that a vulnerability in an old Magic Eden trading contract, Payment Processor V2, is being exploited to take NFTs from wallets that previously listed assets on Magic Eden. Decentraland's own smart contracts were not compromised — the exploit is specific to the external Magic Eden contract.
The Decentraland Foundation and @RegenesisLabs acted to identify exposed wallets on Ethereum and Polygon and move Decentraland assets out of reach:
Anyone who listed Decentraland assets on Magic Eden is advised to check their wallet with Revoke.cash's Magic Eden exploit checker and revoke Payment Processor V2 approvals on Ethereum and Polygon. Rescued assets will be returned automatically once approvals are revoked — no claim link, payment, or signature is required.